Vulnerability MAL-2026-16202
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 days ago
September 14, 2026 at 12:00 AM UTC
Malicious code in webpackbootstrapscripts (npm)
5.110.3
5.110.3
Summary
Malicious code in webpackbootstrapscripts (npm)
Details
[email protected] typosquats bootstrap and ships a disguised in-browser proxy kit. Its bundled loader (index-z2b7r4.js) XOR-decodes a list of endpoints with a fixed key and injects remote scripts from https://dyingefforlessefforlessours.com via document.head.appendChild, then boots a Scramjet/wisp WebSocket proxy that routes page traffic through operator-controlled relays. The loader matches (same sha256) sibling packages webpackbootstrapscripts and @zaka13/thing by the same publisher (zaka13). Harm is browser-side when the asset is served; no install script runs.
Impacted packages
Timeline
Published
2 days ago
September 14, 2026 at 12:00 AM UTC
Last Modified
14 hours ago
September 16, 2026 at 01:30 AM UTC